Ransomware gangs now outing victim businesses that don't pay
krebsonsecurity.com
krebsonsecurity.com
Kidding aside, these are serious breaches and it would be good to at least have the names of the companies out there. By law they were required to report anyway and the local authorities in turn would publish / fine.
So downloading this data would be strictly off-limits but the names of the companies should be public so that people at least have a chance to know that they have been affected.
First, the message was "backup your data". Now, they also added "encrypt your data"!
Everyone has jobs to do and they can't do them effectively if you need them to think through information security for every interaction. You have to build the rails and create a safe work area. User education is truly the last layer because if everything fails maybe the user will remember something we said.
Rogue employees require a lot more traditional security and trust. Someone could always just physically destroy company property, and Sally could always approve fraudulent transactions, so you have to start there and it'll get you pretty far.
How come keystrokes aren't encrypted yet? I don't really have the foggiest idea how my computer interprets the data that comes from me turning on and off a bunch of switches in rapid succession but it's odd to me that we all kind of accept that we're screwed if a bad actor starts logging our keystrokes.
It's the equivalent of having a camera above the keyboard. Really not much you can do there.
But like I said, I know nothing about the computer magic behind my keystrokes.
Compartmentalization is a guiding principle for things like spy networks. It's also how you make critical equipment able to survive failures.
I'd rather just call them "criminals".
The "cyber" prefix is generally unnecessary, and sometimes even misleading.
Spiderterrorism
Spider-espionage
Spiderspace
Spidercrime
Yep, terrifying.
Maybe it's time for an update? :)
But to make the data public, they have to download all the data first. This might be detected.
I know from several companys who did set up the complete network again.
The most prominent company I know at moment is Pilz (pilz.com). There website was almost down for a month. Now after 2 months it possible to download datasheets and manuals again.
If my company is beset by ransomware, and they claim they will release it I can either assume:
1. They have extracted the data and therefor have to assume they arent just going to delete it because I sent them a check.
2. They are bluffing and have only encrypted my data.
I dont think I can count on #2.
People demanding death sentences and that Iran/China/Russia/North Korea be nuked, over private business data leaks?
It's like the problem of attribution never has existed, nowadays the "smoking cyber guns" are apparently everywhere.
https://krebsonsecurity.com/2019/12/ransomware-gangs-now-out...
What needs to become the norm for the US Govt response to these gangsters is for them to get in the habit of doing what they did in the Evil Corp case: Once the offenders are positively identified, get the Treasury to issue financial sanctions on them that prevent the crooks from transacting with people and businesses outside their home country.
https://krebsonsecurity.com/2019/12/inside-evil-corp-a-100m-...
This is perhaps the most effective tool in law enforcement’s hands to combat cybercrime — short of apprehending the bad guys. None of these dudes want to be stuck in Russia, and they sure as hell don’t want all their money kept their either. Rather, they tend to launder it by investing in properties and other businesses outside their own country. Making it a crime for others to accept their money is an extremely effective way of frustrating these criminals.
You can, like, exchange one currency for another. How do you think people buy oil with every currency other than the dollar?
Either lose the pennies you would've made from data mining or lose real millions from getting ransomed. Your choice.
It works only for storage service basically (or messaging, where the two have the keys).
For e-commerce, the client can sign his or her address with the shipper's public key, so that only the shipper and the recipient are guaranteed to know the address. To the user, this could happen transparently without any change in UX, where the e-commerce website acts like a keyserver.
For email addresses, phone numbers, names, etc. it is more difficult. You can't just store a hash of the email address if you want to ever be able to email your customers.
Internal documents can be more trivially end-to-end encrypted. Imagine the whole company shares a WhatsApp group chat. Nobody has to ever hold a plaintext copy of an internal document. Only permit access on company devices which hold the keys in hardware.
Yes a lot can still be done with security on machines and traffic, etc.... But the human factor is hard to control and fix. If someone sent out a phishing email with a link that said "click here to see magical unicorns jumping over a rainbow", someone would click it, i know poeple i work with who would click it. It gets, frustrating at least for me, since i have a lot to do with security where i am at.
What reasonable person thinks that clicking on a link is a potentially dangerous act? That's how everything is done these days, and we're not supposed to trust that it is a safe operation?
We're not supposed to plug in a USB drive to see what's on it? That's pretty much all they're for!
0-day bugs and lacking updates make promiscuous internet use hazardous, yet people expect browser to do everything a PC can.
Why would the hosting company/ISP be at risk? Just run it from a non-US extradition friendly country, and say that you won't take any action unless there's a court order from your local court.
Another checkmark in the category of not making paying ransoms illegal. This whole new data-dump threat vector just doubles down the threat to keep it quiet and pay it out.
Law enforcement will rarely catch enough of these companies who do pay to make it meaningful. Most of these are small time private businesses who are more than capable of keeping it quiet, without information release obligations to investors.
We need public education campaigns for backing up company data offsite and encouraging more companies investing in security firms to up the bar for these attacks. It's the only way they'll slow down.
Aren't these mutually exclusive positions?
Isn't the clear course of action then to report, pay the fine and tell the criminals to get lost?
Maybe that wasn't meant as such, but it comes across, at least to me, as an argument that making non-disclosure punishable was a bad idea. If that was the argument, then I'd point out that the same thing can be said of criminalising any offence at all.
and this law does give an incentive to cover up, as long as the ransom is < fines .
(12) ‘personal data breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;
So it seems that a ransomware attack is considered a breach - as it should be - and neither exfiltration nor disclosure is necessary for that to be the case.
Any sort of access is a weapon in the hands of a malicious hacker. Penalties for allowing it to happen are weapons in the hands of those trying to do something about it.
i think the best thing to do is to minimize sensitive data completely, no logs no nothing. But then you move the burden of security to the end user (e.g. they 'll have to re-enter their credit card every time), which is probably higher risk.
The reality is that you are creating a false dichotomy / straw man here. While reducing the amount of personal information that is gathered and stored should be the first response, that which remains can be handled appropriately with encryption and defense-in-depth.